Skip to content
firewallpulse
Bits, bytes and breaking security news
Data Breaches

Unprotected Internet-Facing Interfaces at 8,547 Global Renewable Sites Enable Remote Turbine Control

Dutch and Israeli researchers identified thousands of unprotected renewable energy systems across 35 nations, many allowing direct remote control.

Unprotected Internet-Facing Interfaces at 8,547 Global Renewable Sites Enable Remote Turbine Control
Illustration: Firewall Pulse

Key points

  • Researchers found 8,547 internet-facing systems at wind and solar sites across 35 countries.
  • Many exposed interfaces include login screens or turbine controls with remote stop buttons.
  • Operators in Spain, Greece, Italy and Germany account for the majority of confirmed systems.

Dutch National Cyber Security Centre (NCSC-NL) and cybersecurity firm Modat identified 8,547 exposed control systems at European wind farms and solar parks. These systems, located across 35 countries in and around the EU, were found to be directly reachable from the public internet despite security best practices requiring isolation. The discovery highlights a widespread failure in network segmentation for critical energy infrastructure.

Root cause

The exposure stems from misconfigured network perimeters that allow direct internet access to operational technology. According to Help Net Security, the systems range from simple login pages to full turbine control interfaces. This misconfiguration leaves critical command-and-control functions vulnerable to unauthenticated access, bypassing standard enterprise security layers that should block external traffic from reaching industrial control networks.

Attack path

Attackers can browse to these exposed systems using standard web browsers. Help Net Security reports that some interfaces offer a "Stop" button to anyone with access, allowing remote shutdown of turbines. Other systems present login screens that may be susceptible to credential stuffing or brute-force attacks. The direct internet connectivity eliminates the need for initial exploitation of external-facing servers, granting immediate access to critical controls.

Affected versions

The report does not specify software versions or vendors. The findings cover a broad range of control systems across multiple manufacturers and operators. Help Net Security notes that the actual number of exposed systems is likely higher than the 8,547 confirmed. Operators in Spain, Greece, Italy and Germany account for the largest share of the identified exposures, suggesting regional variations in security implementation or monitoring practices.

Mitigation

No vendor patches or specific fixes have been confirmed for these misconfigurations. The issue is primarily one of network architecture and configuration rather than software vulnerability. Operators must verify that control systems are not directly addressable from the internet. Internal audits of firewall rules and network segmentation are required to ensure that operational technology remains isolated from public networks until proper security controls are verified.

What to do and how to stay safe: NCSC-NL

  • Audit all internet-facing assets to identify any operational technology or control systems that should be isolated.
  • Verify that firewall rules strictly block inbound traffic to industrial control networks from public IP ranges.
  • Monitor network logs for unauthorized access attempts to sensitive internal interfaces or login screens.
  • Implement network segmentation to ensure that critical control functions are not reachable from general corporate networks.

General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

How many systems were found exposed?

Researchers identified 8,547 internet-facing systems across 35 countries in and around the EU.

Which countries are most affected?

Operators in Spain, Greece, Italy and Germany account for most of the confirmed exposed systems.

Can attackers remotely stop turbines?

Yes, some exposed control pages offer a Stop button accessible to anyone with a web browser.

Sources

  1. Help Net Security
  2. Security Magazine
NCSC-NLModatwind farmssolar parkscritical infrastructure

Related stories

How Breach Notification Letters Work: The Hidden Mechanics

The notification letter is the final output of a legal and technical triage process that often begins weeks before you receive it, shaped by regulatory thresholds rather than pure impact.